2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-24081HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-24080HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-24079HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-24078HIGH7Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-24077HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-24076HIGH7.3Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
CVE-2025-24075HIGH7.8Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-24072HIGH7.8Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges...
CVE-2025-24070HIGH7Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a net...
CVE-2025-24067HIGH7.8Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
CVE-2025-24066HIGH7.8Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
CVE-2025-24064HIGH8.1Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
CVE-2025-24061HIGH7.8Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feat...
CVE-2025-24059HIGH7.8Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to ele...
CVE-2025-24057HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-24056HIGH8.8Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.
CVE-2025-24051HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-24050HIGH7.8Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVE-2025-24049HIGH8.4Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (C...
CVE-2025-24048HIGH7.8Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVE-2025-24046HIGH7.8Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
CVE-2025-24045HIGH8.1Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to...
CVE-2025-24044HIGH7.8Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
CVE-2025-24043HIGH7.5Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network.
CVE-2025-24035HIGH8.1Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now